CVE-2021-39935
high
KEV
CVSS v3
—
CVSS v2
—
VIR risk
9.5
Description
GitLab Community and Enterprise Editions contain a server-side request forgery vulnerability which could allow unauthorized external users to perform Server Side Requests via the CI Lint API.
CISA KEV
- Vendor
- GitLab
- Product
- Community and Enterprise Editions
- Due date
- 2026-02-24
Predictions
Exploit likelihood
99%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cisa-kev — https://about.gitlab.com/releases/2021/12/06/security-release-gitlab-14-5-2-released/ ; https://nvd.nist.gov/vuln/detail/CVE-2021-39935
Vendor advisory: arch — https://security.archlinux.org/ASA-202112-10
Exploits
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| arch | fixed | 14.5.2-1 |
References
Verify integrity in audit chain (admin only). AS-IS.